CVE-2015-2752: Input Validation
The XENDOMCTLmemorymapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2752?
CVE-2015-2752 is classified as a medium severity vulnerability, as it can lead to denial of service through excessive CPU consumption.
How do I fix CVE-2015-2752?
To fix CVE-2015-2752, update to a patched version of Xen or Fedora that addresses the vulnerability.
What types of systems are affected by CVE-2015-2752?
CVE-2015-2752 affects Xen versions from 3.2.x through 4.5.x specifically when using PCI passthrough devices.
What exploitation method is used for CVE-2015-2752?
CVE-2015-2752 can be exploited by local x86 HVM domain users sending crafted requests to the device model.
Can CVE-2015-2752 impact the host system?
Yes, CVE-2015-2752 can impact the host system by causing increased CPU consumption leading to a denial of service.